Threat Intelligence

Working Exploit Released for AnyDesk Linux Flaw That Grants Root Access Before Anyone Approves a Connection

The Hacker News · 9 Oct 2026
Key Takeaway If your business runs AnyDesk on Linux, update to version 8.0.3 or later (ideally 8.1.0) now, and block access to TCP port 7070 wherever you cannot patch immediately.

Security researchers have published a full working exploit, named AnyPwn, for a serious flaw in AnyDesk on Linux. The bug is a heap buffer overflow in the remote desktop tool's session protocol. It lets an attacker run commands with root access before anyone approves the connection. The code appeared on GitHub on October 8.

AnyDesk fixed the issue in version 8.0.3 in June, but its changelog described it only as "fixed a bug that could lead to a crash". No CVE has been assigned as of October 9, and there is no formal security advisory. The published exploit works only over direct TCP connections on port 7070, and it is probabilistic: if the memory layout does not line up, the service crashes instead of running the attacker's command. The offsets target AnyDesk Linux 8.0.2, so other builds would need different values. Researchers imply earlier versions such as 8.0.1 may share the flaw, but this is unconfirmed.

AnyDesk has said the problem is limited to direct connections on Linux, and that Windows and macOS are not affected. The researchers say the same vulnerable code can be reached through AnyDesk's relay servers, which they validated with a Frida instrumentation trigger, but they did not demonstrate a full exploit over relays. That question remains unresolved. Administrators should update to at least 8.0.3 (the latest release is 8.1.0). If that is not possible straight away, restrict access to TCP port 7070.

AnyDesk Linux remote code execution patching remote access

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.